Skip to content
ThreatCluster

Citrix NetScaler ADC and Gateway XSS Vulnerability Disclosed

First seen 12 Nov 2025, 21:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Cloud Software Group has disclosed a cross-site scripting (XSS) vulnerability in NetScaler ADC and NetScaler Gateway products, tracked as CVE-2025-12101. This flaw allows attackers to inject malicious scripts into web pages, potentially leading to session hijacking and data theft. The vulnerability has a CVSSv4 score of 5.9, indicating moderate severity and reliance on user interaction.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 198d ago How this analysis works

More articles in this cluster (2)